ZeroHour

CVE-2020-13596

CVSS 3.1
6.1 medium
EPSS
3%p86
Published
()
Modified
Description

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

Vendors
djangoprojectfedoraprojectcanonicalnetappdebianoracle
Products
django, fedora, ubuntu linux, sra plugin, steelstore cloud integrated storage, debian linux, zfs storage appliance kit
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.